PT-2023-6402 · Pyminizip+7 · Pyminizip+7

Zmodem

·

Published

2023-08-11

·

Updated

2026-04-09

·

CVE-2023-45853

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions zlib versions through 1.3 pyminizip versions through 0.2.6
Description The issue is related to an integer overflow and resultant heap-based buffer overflow in the zipOpenNewFileInZip4 64 function of the MiniZip package in zlib, which can be triggered by a long filename, comment, or extra field. This can potentially allow a remote attacker to impact the integrity, availability, and confidentiality of protected information. The vulnerability is also present in pyminizip due to its use of an affected zlib version. According to recent data, this issue remains a top Android exploit, with a rising trend in recent months.
Recommendations For zlib versions through 1.3, update to a version that fixes the integer overflow issue in the zipOpenNewFileInZip4 64 function. For pyminizip versions through 0.2.6, update to a version that uses a fixed zlib version or restricts the use of the vulnerable MiniZip code through its compress API. As a temporary workaround, consider disabling the zipOpenNewFileInZip4 64 function until a patch is available. Restrict access to the vulnerable MiniZip code to minimize the risk of exploitation.

Fix

Heap Based Buffer Overflow

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-3837
ALT-PU-2024-8467
ALT-PU-2024-8890
AZL-31294
AZL-31298
AZL-31496
AZL-31497
AZL-31500
AZL-33350
AZL-34597
AZL-35229
AZL-35242
AZL-35295
AZL-35400
AZL-38040
AZL-42720
AZL-42741
AZL-43435
AZL-43522
AZL-43525
AZL-43609
AZL-44043
AZL-44127
AZL-44436
AZL-44985
AZL-61279
AZL-61795
BDU:2023-07116
CVE-2023-45853
DLA-3670-1
ECHO-8ED3-9419-847F
GHSA-MQ29-J5XF-CJWR
GHSA-Q5FM-55C2-V6J9
MGASA-2023-0312
OESA-2023-1751
OPENSUSE-SU-2023_4215-1
OPENSUSE-SU-2023_4217-1
OPENSUSE-SU-2024:13363-1
OPENSUSE-SU-2024:13462-1
OPENSUSE-SU-2025:14857-1
OPENSUSE-SU-2026:20487-1
ROSA-SA-2024-2463
SUSE-SU-2023:4215-1
SUSE-SU-2023:4216-1
SUSE-SU-2023:4217-1
SUSE-SU-2023_4215-1
SUSE-SU-2023_4216-1
SUSE-SU-2023_4217-1
SUSE-SU-2024:2431-1
SUSE-SU-2026:20659-1
SUSE-SU-2026:20709-1
SUSE-SU-2026:21013-1
SUSE-SU-2026:21151-1
USN-7107-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Suse
Ubuntu
Pyminizip
Zlib